From Paradigm Shift to Audit Rift: Exploring Vulnerabilities and Audit Tips for TON Smart Contracts

📅 2025-09-13
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
TON smart contracts face unique security challenges—including asynchronous message passing and a multi-layered architecture—yet lack audit methodologies tailored to their execution model. This paper systematically analyzes 233 real-world vulnerabilities extracted from 34 professional audit reports, thereby establishing the first comprehensive, structured auditing framework and standardized checklist specifically designed for the TON ecosystem. The framework is explicitly aligned with TON’s asynchronous execution semantics, bridging the practical gap between mature Ethereum auditing methodologies and the emerging TON platform. Through mixed-method (qualitative and quantitative) case studies, we identify high-risk anti-patterns—such as message reentrancy and cross-contract state inconsistency—and distill actionable, rule-based security checks. Our contributions significantly enhance developers’ and auditors’ ability to detect and remediate prevalent TON-specific vulnerabilities, thereby improving the security and reliability of TON-based applications.

Technology Category

Application Category

📝 Abstract
The Open Network (TON) is a high-performance blockchain platform designed for scalability and efficiency, leveraging an asynchronous execution model and a multi-layered architecture. While TON's design offers significant advantages, it also introduces unique challenges for smart contract development and security. This paper introduces a comprehensive audit checklist for TON smart contracts, based on an analysis of 34 professional audit reports containing 233 real-world vulnerabilities. The checklist addresses TON-specific challenges, such as asynchronous message handling, and provides actionable insights for developers and auditors. We also present detailed case studies of vulnerabilities in TON smart contracts, highlighting their implications and offering lessons learned. By adopting this checklist, developers and auditors can systematically identify and mitigate vulnerabilities, enhancing the security and reliability of TON-based projects. Our work bridges the gap between Ethereum's mature audit methodologies and the emerging needs of the TON ecosystem, fostering a more secure and robust blockchain environment.
Problem

Research questions and friction points this paper is trying to address.

Identifying vulnerabilities in TON smart contracts
Developing audit checklist for TON-specific security challenges
Bridging Ethereum audit methods with TON ecosystem needs
Innovation

Methods, ideas, or system contributions that make the work stand out.

Comprehensive audit checklist for TON
Analyzed 34 reports with 233 vulnerabilities
Addresses asynchronous message handling challenges
🔎 Similar Papers
No similar papers found.
Yury Yanovich
Yury Yanovich
Skolkovo Institute of Science and Technology
BlockchainStatisticsMachine learning
S
Sergey Sobolev
Positive Technologies, Moscow, Russia
Y
Yash Madhwal
Skolkovo Institute of Science and Technology, Moscow, Russia
K
Kirill Ziborov
Positive Technologies, Moscow, Russia; Lomonosov Moscow State University, Moscow, Russia
V
Vladimir Gorgadze
Blockchain Department, Moscow Institute of Physics and Technology, Moscow, Russia
V
Victoria Kovalevskay
Faculty of Computer Science, HSE University, Russia
E
Elizaveta Smirnova
Blockchain Department, Moscow Institute of Physics and Technology, Moscow, Russia
M
Matvey Mishuris
Blockchain Department, Moscow Institute of Physics and Technology, Moscow, Russia
Subodh Sharma
Subodh Sharma
Indian Institute of Technology, Delhi, India